Security

Error in 'SearchParser': Missing a search command before ' '.

alenseb
Communicator

Hi,

I am trying to access one of my saved Searches, but this error is shown all of a sudden.
My syntax is correct as the same code was working sometime back.
Is this a product bug?

Please help.

Thanks!!

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

0 Karma

ryonts
Explorer

I discovered today that after modifying a saved search to format it for better readability, this error showed up. The problem was that in formatting it, I added some CRLF characters. Afterwards, the error showed up. For some reason, CRLF are NOT ignored, but affect the search string. Hopefully this can help your situation. (I HATE unformatted search strings, too difficult to read when all jumbled up!)

MarioM
Motivator

to get help you need to give more infos:
-post the complete search
-splunk version
-permissions of the searches/report/dashboards/apps...

0 Karma

alenseb
Communicator

Just read somewhere for these of errors, you have to re-install.
Any idea on why?

0 Karma

alenseb
Communicator

i haven't changed anything.

0 Karma

MuS
SplunkTrust
SplunkTrust

so what did change since it last was working?

0 Karma

alenseb
Communicator

The search works just fine, but when i search as a | savedsearch i get the error.

Also the same SavedSearch command was working fine sometime back.

0 Karma

lguinn2
Legend

We need to see the actual search text. Go to the Manager and edit the saved search. Copy the search into a comment.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...